Repository navigation
Super epic: Simplify LibreCode GitHub workflow and release architecture #181
Description
Activity
vitormattos commented
on Sep 24, 2026 MemberAuthorMore actionsPhase 0 inventory refresh — initial findings
Current references and classification:
LibreCodeCoop/extract: several workflows still use remote reusable-workflow callers fromLibreCodeCoop/github-workflows/.github/workflows/*. These are current CI functions, but the consumption model is obsolete. They must be converted to materialized workflows during consumer cutover, not merely repointed.LibreCodeCoop/profile_fields:.github/workflows/release-nextcloud-app.ymlis a retired release path and should be removed, not redirected..github/workflows/sync-workflow-templates.ymlis current and should move to the new catalog/helper owner after the catalog migration..github/workflows/appstore-build-publish.ymlcontains current release helper references that must move to release-tool ownership after the release compatibility/consolidation phases.
LibreSign/libresign: current references exist in prepare-release, release-metadata, nightly-release, first-merged-pr-comment, and sync-workflow-templates. These remain current behavior and will be cut over only after the destination implementations are validated.LibreSign/documentation: release-process docs still describe github-workflows as orchestration owner; update after implementation cutover so documentation describes the final architecture.- Source repository drift confirmed:
workflow-catalog.jsondoes not listrelease-nextcloud-app, butworkflow-templates/release-nextcloud-app.yml, its properties metadata, license sidecar, and a workflow-family documentation entry still exist. This is a clearly retired artifact and will be removed in Phase 0.
Architectural discovery:
extractdemonstrates an existing reusable-workflow consumption path, while the target architecture requires complete materialized workflows in consumers. Consumer migration therefore needs to replace that model rather than preserve it.No execution-order change is needed. I am removing only the clearly retired source artifact now, then proceeding to release-tool#55 before any large structural migration.
vitormattos commented
on Sep 24, 2026 MemberAuthorMore actionsPhase 0 cleanup completed: #182 was merged as
c63cc243322c6c7d4fe6580adae6c8c9fa7ebe89after actionlint, zizmor, REUSE, workflow-policy, and Python test checks all passed. The retiredrelease-nextcloud-apptemplate, catalog metadata sidecar, license sidecar, and stale workflow-family documentation entry are now removed from the source repository. No compatibility path was retained. The remaining inventory findings are intentionally carried forward to their ordered migration phases (notably materializing current reusable-workflow consumers during consumer cutover).vitormattos commented
on Sep 24, 2026 MemberAuthorMore actionsPhase 1 completed. LibreCodeCoop/release-tool#55 landed via release-tool#61 (
34cadc7defa914397dc852eb63c5a5cde6f5a6ec) with all repository gates green. The compatibility harness is process-based, uses deterministic local/fake GitHub fixtures, preserves redirect credential and archive traversal safety checks, and isolates implementation details behind a test target so the same scenarios can be exercised by the PHP port. Proceeding in the documented order to Phase 2 / release-tool#57.vitormattos commented
on Sep 24, 2026 MemberAuthorMore actionsPhase 1 is complete. LibreCodeCoop/release-tool#61 merged as
34cadc7defa914397dc852eb63c5a5cde6f5a6ec; release-tool#55 is closed. The compatibility suite is PHPUnit-driven, keeps Python only as isolated test fixtures with recorded provenance, exercises authorization, stable selection, artifact validation/restore security, and release-note behavior against deterministic local fixtures/fake HTTP, and passed PHPUnit, PHP quality, Infection, PHAR, workflow quality, and REUSE on the merge candidate. Phase 2 has started with release-tool#57; the first PHP port slice is PR #62.vitormattos commented
on Sep 24, 2026 MemberAuthorMore actionsAll implementation phases are complete.
- release-tool consolidation epic is closed;
- .github catalog epic is closed;
- LibreSign, extract and profile_fields consumers are cut over;
- documentation reflects the resulting architecture;
- github-workflows implementation was removed in PR chore: retire github-workflows repository #183 and its main branch contains only retirement/license/security files;
- no current consumer file checked directly depends on this repository.
The only remaining program-level condition is the GitHub repository archive/read-only setting. GitHub currently reports
archived=false, and the installed connector does not expose repository administration mutations. Keeping this super epic open until that single administrative action is performed, after which #180 and this issue can be closed.vitormattos commented
on Sep 24, 2026 MemberAuthorMore actionsFinal program re-audit on 2026-09-24:
- release-tool#60 is closed;
- Epic: Make .github the single organization workflow catalog .github#58 is closed;
- no current code-search hit remains for
LibreCodeCoop/github-workflowsacross LibreCodeCoop or LibreSign; - no current code-search hit remains for retired
release-nextcloud-appacross either organization; - github-workflows
maincontains only retirement/license/security files; - repository state is still
archived=false.
Therefore Phases 0–7 implementation work is complete except for the final repository archive/read-only administration flag. There is no remaining code change to make without inventing work or preserving obsolete compatibility. Once the repository is archived, #180 and this super epic can be closed.
vitormattos commented
on Sep 24, 2026 MemberAuthorMore actionsLibreSign release-workflow correction is complete.
Merged:
- ci: keep release-tool implementation out of workflows LibreSign/libresign#8683 on main;
- [stable35] ci: backport release-tool cutover to stable35 LibreSign/libresign#8680 on stable35;
- [stable34] ci: backport release-tool cutover to stable34 LibreSign/libresign#8681 on stable34;
- [stable33] ci: backport release-tool cutover to stable33 LibreSign/libresign#8682 on stable33.
The follow-up removes the accidental consumer-side exposure introduced by #8679: no manual Release Tool PHAR bootstrap/checksum blocks and no direct consumer calls to internal release commands. Current main uses pinned Release Tool Actions for stable selection, artifact validation, release notes, metadata inspection, prepare, post-merge, and publication.
GitHub code search still surfaces old pre-merge commits containing the temporary PHAR/bootstrap implementation, but direct reads of current main confirm those blocks are gone. No current LibreSign workflow references LibreCodeCoop/github-workflows.
Program state remains blocked only on archiving LibreCodeCoop/github-workflows itself (
archived=false).vitormattos commented
on Sep 24, 2026 MemberAuthorMore actionsFinal audit found two residual items after the earlier implementation cutover:
LibreCodeCoop/release-toolstill contained the one-shot.github/workflows/publish-v0.10.16.ymlpublisher. This was migration/release residue and has now been removed by release-tool#74.- The temporary Python reference harness remained under
tests/Fixtures/PythonReferenceafter parity had already been demonstrated. release-tool#75 removes that retired implementation while preserving the behavioral/security scenarios against the PHP target.
Documentation source in
LibreSign/documentationis current and no longer referencesLibreCodeCoop/github-workflows, andgh-pagescontains the corrected generated HTML. However, the public custom domaindocs.libresign.coopis still serving substantially older content. LibreSign/documentation#104 tracks that publication/origin discrepancy.Because the published documentation is still stale, I am not treating archival as fully complete yet even though organization code search has no current
LibreCodeCoop/github-workflowsreferences.vitormattos commented
on Sep 24, 2026 MemberAuthorMore actionsFinal technical audit completed after the follow-up cleanup.
Validated current state:
- release-tool#74 removed the forgotten one-shot
publish-v0.10.16.ymlpublisher; - release-tool#75 removed the temporary release-specific Python reference implementation after parity, while retaining the behavioral/security scenarios against PHP;
- release-tool#76 aligned the architecture documentation with the actual public Action boundary;
- current
release-tool/.github/workflowscontains only the normal CI/release workflows; no version-specific one-shot publisher remains; - searches across LibreCodeCoop and LibreSign return no current
LibreCodeCoop/github-workflowsreferences; - searches across both organizations return no current
release-nextcloud-appreferences; - LibreSign/documentation source contains no current
github-workflowsreferences; - the generated
gh-pagesrelease-process HTML is current and describes release-tool/.github ownership correctly. External web search still exposes a several-days-old crawl of the previous docs, which is stale indexing rather than a current repository dependency; documentation#104 tracks live-domain/search refresh verification.
There is no remaining technical dependency on this repository. The only program exit action still outstanding is setting
LibreCodeCoop/github-workflowsto archived/read-only; GitHub currently reportsarchived=false.- release-tool#74 removed the forgotten one-shot
Objective
Simplify LibreCode's GitHub automation architecture by removing unnecessary repository layers, placing responsibilities with their natural owners, preserving testability, and retiring
LibreCodeCoop/github-workflowswhen the migration is complete.Target architecture
Release implementation is owned separately by:
There must be no permanent
github-workflowshop between upstream, the organization catalog, and consumers.Child epics
Architectural boundaries
LibreCodeCoop/.github owns
actions/sync-workflows;actions/first-merged-pr-comment;LibreCodeCoop/release-tool owns
Public Action API should converge on the actual lifecycle stages:
actions/prepareactions/post-mergeactions/publicationExisting helper Actions must be treated as implementation details unless an independent public use case is demonstrated.
github-workflows owns nothing permanently
This repository is only a temporary migration source. It must be archived after all current responsibilities have moved or been removed.
Non-negotiable rules
Materialized workflows
Consumer repositories must keep complete workflow YAML files. Do not replace the organization catalog with reusable-workflow callers that hide workflow implementation behind
jobs.<name>.uses.Composite/custom Actions are allowed where they encapsulate procedural implementation while keeping the workflow structure visible.
No legacy preservation by default
Migration is not a copy-everything exercise.
If a workflow, script, test, generated file, compatibility path, manifest or document is not part of the target architecture, remove it from the source repository instead of migrating it.
Do not introduce compatibility shims solely to keep obsolete
LibreCodeCoop/github-workflowspaths alive.Known retired item:
workflow-templates/release-nextcloud-app.yml— remove it, its metadata, and references/tests/docs that only exist for that retired workflow.Apply the same rule to any other stale artifact found during implementation.
Testability
Reducing layers must not reduce test coverage.
Preserve or improve tests for:
Tests must live with the code they validate.
Python to PHP release migration
Do not translate release Python line-by-line.
Before replacing release-specific Python:
Prefer minimal PHP infrastructure. Add external SDKs only when a concrete benefit is demonstrated.
Execution order
Work in this order unless a discovered hard dependency requires a documented adjustment.
Phase 0 — Inventory and cleanup
LibreCodeCoop/github-workflowsrelease-nextcloud-appDo not begin large code moves before this inventory is current.
Phase 1 — Establish release behavioral safety net
Implement release-tool#55 first.
This phase is a prerequisite for replacing release Python.
Phase 2 — Consolidate release-tool
Execute the remaining work in release-tool#60.
Recommended order:
release-tool.Do not remove the reference Python until parity is achieved.
Phase 3 — Move the workflow catalog to .github
Execute LibreCodeCoop/.github#58.
Recommended order:
sync-workflows;first-merged-pr-comment;/workflow-templates;workflow-catalog.jsonstill has a real purpose; remove it if it only served the old publication model;Phase 4 — Consumer cutover
Review every current consumer individually.
Known references include:
LibreCodeCoop/extract
Managed workflow files currently reference
LibreCodeCoop/github-workflows.Repoint current functionality to the new owner.
LibreCodeCoop/profile_fields
Known files include:
.github/workflows/release-nextcloud-app.yml.github/workflows/sync-workflow-templates.yml.github/workflows/appstore-build-publish.ymlDo not repoint the retired
release-nextcloud-app.ymlto a compatibility path. Decide whether the repository should adopt the currentprepare-releasemodel; otherwise remove the retired workflow.LibreSign/libresign
Known files include:
.github/workflows/prepare-release.yml.github/workflows/release-metadata.yml.github/workflows/first-merged-pr-comment.yml.github/workflows/nightly-release.yml.github/workflows/sync-workflow-templates.ymlMove current Action references to their new immutable owners.
LibreSign/documentation
Update release-process documentation so it describes the resulting architecture, not the transition state.
Phase 5 — End-to-end validation
Before retiring this repository, validate real flows:
nextcloud/.github → LibreCodeCoop/.github → consumer;prepare → post-merge → publication;Review actual workflow logs, not only static tests.
Phase 6 — Remove the old architecture
Only after cutover:
catalog-publish.yml;sync_catalog.pyif it has no remaining role;Phase 7 — Final audit and archival
Search both organizations again for:
LibreCodeCoop/github-workflowsrelease-nextcloud-appResolve every remaining current reference.
Then:
Change-management rules
For each meaningful unit of work:
Do not put secrets, token values, private keys, credentials, or secret contents in issues, commits, logs or documentation. Public secret/variable names and required permission descriptions are fine.
Definition of done
This program is complete when:
LibreCodeCoop/.githubis the single workflow-catalog intermediary;LibreCodeCoop/release-toolowns the entire release product;LibreCodeCoop/github-workflowsremains;